Pal-Stefan Murvay

dblp:81/10328 · DBLP profile ↗
← Back
23ranked-venue papers
5as first author
7since 2021 · last 2023
0000-0002-0330-4523ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 16 · 4 first-author · 6 since 2021Artificial intelligence and machine learning · 2Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Systems, architecture and hardware · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author
YearPublicationVenuePosition
2023 CAN-LOC: Spoofing Detection and Physical Intrusion Localization on an In-Vehicle CAN Bus Based on Deep Features of Voltage Signals
abstract
The Controller Area Network (CAN), which is used for communication between in-vehicle devices, has been shown to be vulnerable to spoofing attacks. Voltage-based spoofing detection (VBS-D) mechanisms are considered state-of-the-art solutions, complementing cryptography-based authentication whose security is limited due to the CAN protocol’s limited message size. Unfortunately, VBS-D mechanisms are vulnerable to poisoning performed by a malicious device connected to the CAN bus, specifically designed to poison the deployed VBS-D mechanism as it adapts to environmental changes that take place when the vehicle is moving. In this paper, we harden VBS-D mechanisms using a deep learning-based mechanism which runs immediately, when the vehicle starts; this mechanism utilizes physical side-channels to detect and locate physical intrusions, even when the malicious devices connected to the CAN bus are silent. We demonstrate the mechanism’s effectiveness (100% intrusion detection accuracy and error rates of close to 0%) in various physical intrusion scenarios and varying temperatures on a CAN bus prototype. In addition, we present a deep learning-based VBS-D mechanism that securely adapts to environmental changes. This mechanism’s robustness (99.8% device identification accuracy) is demonstrated on a real moving vehicle.
Efrat Levy, Asaf Shabtai, Bogdan Groza, Pal-Stefan Murvay, Yuval Elovici
IEEE Trans. Inf. Forensics Secur.4
2022 PanoptiCANs - Adversary-Resilient Architectures for Controller Area Networks
Bogdan Groza, Lucian Popa 0003, Tudor Andreica, Pal-Stefan Murvay, Asaf Shabtai, Yuval Elovici
ESORICS (3)4
2022 ECUPrint - Physical Fingerprinting Electronic Control Units on CAN Buses Inside Cars and SAE J1939 Compliant Vehicles
abstract
We fingerprint 54 ECUs from 10 cars, one of them being a heavy-duty vehicle that is compliant to the SAE J1939 standard. These later specifications implemented in commercial vehicles offer concrete sender addresses in every CAN frame, making physical characteristics easier to link to specific ECUs. This is not the case for traffic collected inside passenger cars where the allocation of CAN bus identifiers is non-uniform, without explicit sender and receiver addresses, making ECU identification more challenging. While previous research has shown good separation between ECUs even when single features are used, e.g., skews or maximum voltage level, prior results are based on a small number of cars, while our larger experimental basis proves that single features are likely insufficient to separate between a large number of ECUs. Concretely, for a crisp separation, at least four features seem to be needed, i.e., mean voltage, max voltage, bit time and plateau time, while clock skews or any single voltage feature lead to overlaps. We provide clear experimental bounds on the intra and inter-distances regarding skews and voltage features, not neglecting environmental variations which may occur when the car is running.
Lucian Popa 0003, Bogdan Groza, Camil Jichici, Pal-Stefan Murvay
IEEE Trans. Inf. Forensics Secur.4
2022 Effective Intrusion Detection and Prevention for the Commercial Vehicle SAE J1939 CAN Bus
abstract
Detecting and preventing intrusions on in-vehicle buses is a topic of great importance which may have an even greater significance in the context of commercial vehicles that are liable for the security of the demanding tasks they carry, passengers or goods not least. In this respect, the SAE J1939 protocol, which is a CAN based higher-layer protocol for commercial vehicles, requires special attention due to the existence of both specific procedures in the standard, e.g., address claims and multi-frame transmissions, as well as due to sharp specifications regarding the content of messages which may facilitate the deployment of a more targeted intrusion detection system. Needless to say, most of the research works on CAN intrusion detection are treating in-vehicle traffic as black-box with no concerns over the actual meaning of the frames content. In this context, we pursue the development of a targeted solution for J1939 buses. We collect real-world traffic from a commercial vehicle bus, compliant to the J1939 standard, and make a comprehensive analysis of its structure and content. This allows us to design an effective intrusion prevention system that detects and eliminates in real-time all frames that were manipulated by an adversary by overriding them with error flags. To prove the correctness of our approach, we present results with a proof-of-concept implementation on high-end automotive-grade controllers.
Camil Jichici, Bogdan Groza, Radu Ragobete, Pal-Stefan Murvay, Tudor Andreica
IEEE Trans. Intell. Transp. Syst.4
2021 CAN-SQUARE - Decimeter Level Localization of Electronic Control Units on CAN Buses
Bogdan Groza, Pal-Stefan Murvay, Lucian Popa 0003, Camil Jichici
ESORICS (1)2
2021 CANARY - a reactive defense mechanism for Controller Area Networks based on Active RelaYs
Bogdan Groza, Lucian Popa 0003, Pal-Stefan Murvay, Yuval Elovici, Asaf Shabtai
USENIX Security Symposium3
2021 CANTO - Covert AutheNtication With Timing Channels Over Optimized Traffic Flows for CAN
abstract
Previous research works have endorsed the use of delays and clock skews for detecting intrusions or fingerprinting controllers that communicate on the CAN bus. Recently, timing characteristics of CAN frames have been also used for establishing a covert channel for cryptographic authentication, in this way cleverly removing the need for cryptographic material inside the short payload of data frames. However, the main drawback of this approach is the limited security level that can be achieved over existing CAN bus traffic. In this work we significantly improve on this by relying on optimization algorithms for scheduling CAN frames and deploy the covert channel on optimized CAN traffic. Under practical bus allocations, we are able to extract 3-5 bits of authentication data from each frame which leads to an efficient intrusion detection and authentication mechanism. By accumulating covert channel data over several consecutive frames, we can achieve higher security levels that are in line with current real-world demands. To prove the correctness of our approach, we present experiments on automotive-grade controllers, i.e., Infineon Aurix, and bus measurements with the use of industry standard tools, i.e., CANoe.
Bogdan Groza, Lucian Popa 0003, Pal-Stefan Murvay
IEEE Trans. Inf. Forensics Secur.3
2020 ANTARES - ANonymous Transfer of vehicle Access Rights from External cloud Services
abstract
As car sharing becomes an increasingly common task, mediating user access rights from external servers comes with threats regarding user’s privacy. Clearly, users can be tracked by service mediators, e.g., cloud providers, that manage vehicle fleets, etc. In this work we design and test a simple solution based on oblivious transfer, a well-known and secure cryptographic block, that allows to preserve user’s privacy when gaining access to the vehicle. We test the feasibility of deploying such a solution on Android capable smartphones but also account for potential in-vehicle components, e.g., car head units, that may be soon put to such tasks. We use Microsoft Azure as cloud service provider and deploy a Java implementation, based on the Bouncy Castle cryptographic library, on the server side. Our experimental results show that Android based units are capable of handling the required cryptographic operations and the implementation of the employed protocol can be done by existing open-source support.
Adriana Berdich, Alfred Anistoroaei, Bogdan Groza, Eugen Horatiu Gurban, Pal-Stefan Murvay, Daniel Iercan
VTC Spring5
2019 Performance Evaluation of Elliptic Curve Libraries on Automotive-Grade Microcontrollers
abstract
As cryptography is quickly entering the automotive domain, public-key cryptographic functions are a vital building block and are part of recent industry-proposed standards. Elliptic curves provide a more compact representation for public/private keys making them more suitable for embedded devices with limited amounts of memory. Nonetheless, they provide more compact signatures and open road for identity-based cryptographic primitives by exploiting the flexibility of bilinear pairings. In this work we carry a performance evaluation on some modern libraries, e.g., MIRACL, RELIC, and compare them to the more classical WolfSSL. The evaluation is carried on a state-of-the-art representative controller from the automotive industry, i.e., a 32 bit Infineon TC297. Having a crisper image on computational requirements is relevant for future automotive and industrial applications.
Lucian Popa 0003, Bogdan Groza, Pal-Stefan Murvay
ARES3
2019 Efficient Intrusion Detection With Bloom Filtering in Controller Area Networks
abstract
Due to its cost efficiency, the controller area network (CAN) is still the most wide-spread in-vehicle bus, and the numerous reported attacks demonstrate the urgency in designing new security solutions for CAN. In this paper, we propose an intrusion detection mechanism that takes advantage of Bloom filtering to test frame periodicity based on message identifiers and parts of the data-field which facilitates detection of potential replay or modification attacks. This proves to be an effective approach since most of the traffic from in-vehicle buses is cyclic in nature and the format of the data-field is fixed due to rigid signal allocation. Bloom filters provide an efficient time-memory tradeoff which is beneficial for the constrained resources of automotive grade controllers. We test the correctness of our approach and obtain good results on an industry-standard CANoe-based simulation for a J1939 commercial-vehicle bus and also on CAN with flexible data-rate traces obtained from a real-world high-end vehicle. The proposed filtering mechanism is straightforward to adapt for any other time-triggered in-vehicle bus, e.g., FlexRay, since it is built on time-driven characteristics.
Bogdan Groza, Pal-Stefan Murvay
IEEE Trans. Inf. Forensics Secur.2
2018 Practical Security Exploits of the FlexRay In-Vehicle Communication Protocol
Pal-Stefan Murvay, Bogdan Groza
CRiSIS1
2017 DoS Attacks on Controller Area Networks by Fault Injections from the Software Layer
abstract
The Controller Area Network (CAN) is still the most widely employed bus in the automotive sector. Its lack of security mechanisms led to a high number of attacks and consequently several security countermeasures were proposed, i.e., authentication protocols or intrusion detection mechanisms. We discuss vulnerabilities of the CAN data link layer that can be triggered from the application level with the use of an off the shelf CAN transceiver. Namely, due to the wired-AND design of the CAN bus, dominant bits will always overwrite recessive ones, a functionality normally used to assure priority for frames with low value identifiers. We exploit this characteristic and show Denial of Service attacks both on senders and receivers based on bit injections by using bit banging to maliciously control the CAN transceiver. We demonstrate the effects and limitations of such attacks through experimental analysis and discuss possible countermeasures. In particular, these attacks may have high impact on centralized authentication mechanisms that were frequently proposed in the literature since these attacks can place monitoring nodes in a bus-off state for certain periods of time.
Pal-Stefan Murvay, Bogdan Groza
ARES1
2017 Designing Wireless Automotive Keys with Rights Sharing Capabilities on the MSP430 Microcontroller
Bogdan Groza, Tudor Andreica, Pal-Stefan Murvay
VEHITS3
2017 An Experimental Model for In-vehicle Networks and Subsystems
Bogdan Groza, Eugen Horatiu Gurban, Pal-Stefan Murvay
VEHITS3
2017 LiBrA-CAN: Lightweight Broadcast Authentication for Controller Area Networks
abstract
Despite realistic concerns, security is still absent from vehicular buses such as the widely used Controller Area Network (CAN). We design an efficient protocol based on efficient symmetric primitives, taking advantage of two innovative procedures: splitting keys between nodes and mixing authentication tags. This results in a higher security level when compromised nodes are in the minority, a realistic assumption for automotive networks. Experiments are performed on state-of-the-art Infineon TriCore controllers, contrasted with low-end Freescale S12X cores, while simulations are provided for the recently released CAN-FD standard. To gain compatibility with existent networks, we also discuss a solution based on CAN+.
Bogdan Groza, Pal-Stefan Murvay, Anthony Van Herrewege, Ingrid Verbauwhede
ACM Trans. Embed. Comput. Syst.2
2016 Development of an AUTOSAR Compliant Cryptographic Library on State-of-the-Art Automotive Grade Controllers
abstract
In the light of the recently reported attacks on intra-vehicle networks, it has become clear that cryptography is vital for assuring the security of in-vehicle communications. The current preoccupation of industry professionals in this direction is proved by the inclusion of a comprehensive cryptographic extension in the recent-most version of the AUTOSAR (AUTomotive Open System ARchitecture) stan-dard. In this work we try to give an answer on how prepared are current state-of-the-art automotive controllers for implementing cryptographic primitives and what is the exact cost of software implementations. We take into account automotive grade controllers that range from some of the most constrained platforms, e.g., from 8051 based tire sensors with 8-bit cores, up to 32-bit Infineon TriCore architectures, as well as devices that lay in between these two. We provide experimental results on several symmetric cryptographic primitives, i.e., block ciphers and hash functions, mainly focusing on the lightest constructions proposed in the literature, e.g., Speck, Katan, Blake, as well as on past or current standards, e.g., AES, SHA2 or SHA3. As expected, the results are sparse, some of the platforms being well prepared, capable to easily handle software implementation or carrying dedicated hardware, while for others no dedicated hardware exists while software implementation of current cryptographic standards cannot be handled, especially with the overhead incurred by the cohesion to the AUTOSAR standard.
Pal-Stefan Murvay, Alexandru Matei, Cristina Solomon, Bogdan Groza
ARES1
2016 Evaluating SRAM as Source for Fingerprints and Randomness on Automotive Grade Controllers
abstract
It is well known that the state of uninitialized SRAM provides a unique pattern on each device due to physical imperfections. Both the affinity toward some fixed state as well as the deviation from it can be successfully exploited in security mechanisms. Fixed values provide an efficient mechanism for physical identification and for extracting cryptographic keys while the randomness of bits that flip can be exploited as input for PRNGs that are vital for the generation of ephemeral keys. In this work we try to give an assessment of these two capabilities on several state-of-the art automotive grade embedded platforms. The security of embedded devices inside vehicles has gained serious attention in the past years due to the impact of emerging technologies, e.g., self-driving cars, vehicle-to-vehicle communication, which are futile in the absence of the appropriate security mechanisms. Our examination of several state-of-the-art automotive grade controllers shows that SRAM can offer sufficient entropy and patterns for identification but careful testing is needed as some models fail to provide the expected results
Bogdan Groza, Pal-Stefan Murvay, Tudor Andreica
SECRYPT2
2014 Source Identification Using Signal Characteristics in Controller Area Networks
abstract
The CAN (Controller Area Network) bus, i.e., the de facto standard for connecting ECUs inside cars, is increasingly becoming exposed to some of the most sophisticated security threats. Due to its broadcast nature and ID oriented communication, each node is sightless in regards to the source of the received messages and assuring source identification is an uneasy challenge. While recent research has focused on devising security in CAN networks by the use of cryptography at the protocol layer, such solutions are not always an alternative due to increased communication and computational overheads, not to mention backward compatibility issues. In this work we set steps for a distinct approach, namely, we try to take authentication up to unique physical characteristics of the frames that are placed by each node on the bus. For this we analyze the frames by taking measurements of the voltage, filtering the signal and examining mean square errors and convolutions in order to uniquely identify each potential sender. Our experimental results show that distinguishing between certain nodes is clearly possible and by clever choices of transceivers and frame IDs each message can be precisely linked to its sender.
Pal-Stefan Murvay, Bogdan Groza
IEEE Signal Process. Lett.1
2013 Efficient Protocols for Secure Broadcast in Controller Area Networks
abstract
Controller Area Network is a bus commonly used by controllers inside vehicles and in various industrial control applications. In the past controllers were assumed to operate in secure perimeters, but today these environments are well connected to the outside world and recent incidents showed them extremely vulnerable to cyber-attacks. To withstand such threats, one can implement security in the application layer of CAN. Here we design, refine and implement a broadcast authentication protocol based on the well known paradigm of using key-chains and time synchronization, a commonly used mechanism in wireless sensor networks, which allows us to take advantage from the use of symmetric primitives without the need of secret shared keys during broadcast. But, as process control is a time critical operation we make several refinements in order to improve on the authentication delay. For this we study several trade-offs to alleviate shortcomings on computational speed, memory and bandwidth up to the point of using reduced versions of hash functions that can assure ad hoc security. To prove the efficiency of the protocol we provide experimental results on two representative microcontrollers from the market: a Freescale S12X and an Infineon TriCore, both devices were specifically chosen as they are located somewhat on the extremes of computational power.
Bogdan Groza, Pal-Stefan Murvay
IEEE Trans. Ind. Informatics2
2012 LiBrA-CAN: A Lightweight Broadcast Authentication Protocol for Controller Area Networks
Bogdan Groza, Pal-Stefan Murvay, Anthony Van Herrewege, Ingrid Verbauwhede
CANS2
2011 Secure Broadcast with One-Time Signatures in Controller Area Networks
abstract
We use one-time signatures to assure authenticity for messages that are broadcast over a Controller Area Network (CAN). The advantage is that we can use the simplest one-way functions which are computationally efficient while authentication does not depend on disclosure delays as in the case of protocols based on one-way chains and time synchronization. As the size of the one-time signatures is proportional to the bit length of the signed message, another benefit in using them is due to the reduced size of messages that are broadcast in CAN. To avoid the use of authentication trees, which will allow multiple uses of the one-time signature, but increases the size of signatures as well as memory requirements, we use an upper layer of key-chains with time synchronization in order to commit the public keys that can be further used for signing at any instant. The theoretical results are followed by experimental results on development boards equipped with Free scale S12, a commonly used automotive grade microcontroller. We also benefit from the acceleration offered by the XGATE coprocessor available on S12X derivatives which significantly increases computational performances. To further increase efficiency we also design and use a hardware random number generator which saves computational time that otherwise will be spent to derive fresh key material.
Bogdan Groza, Pal-Stefan Murvay
ARES2
2011 Performance improvements for SHA-3 finalists by exploiting microcontroller on-chip parallelism
abstract
As ubiquitous devices, microcontrollers are deployed in a great variety of applications many of which involve communication over insecure channels that require cryptography. Here we investigate the possibility of using on-chip coprocessors from currently available microcontrollers for increasing computational power by employing parallelism. For this we focus on the analysis of SHA-3 finalists in order to identify features that can lead to an efficient parallel implementation with on-chip coprocessors. Experimental results on a Freescale S12X family microcontroller equipped with an XGATE coprocessor are presented. In this two core environment, speedups between 18 and 73 percents are obtained for the five SHA-3 finalists. In our software implementations BLAKE proves to be the best performer, especially for short messages, followed at some range by Grøstl, then by Skein, Keccak and JH.
Pal-Stefan Murvay, Bogdan Groza
CRiSIS1
2011 Higher Layer Authentication for Broadcast in Controller Area Networks
Bogdan Groza, Pal-Stefan Murvay
SECRYPT2